Description
An Amazon MQ broker inventory documents messaging assets and the services using them. A broker’s presence alone does not indicate a vulnerability.
Potential impact
Unlisted brokers may be missed in access-control and logging reviews, and their owners may be harder to locate during an outage.
Remediation
Record the owning team and connected services, then check network access, authentication, logging, and engine support.
Examples
These excerpts add tags. Supply a supported ActiveMQ version and a separately managed strong password through the variables. Tags alone do not complete the broker’s security configuration.
Before
hcl
resource "aws_mq_broker" "broker" {
broker_name = "app-broker"
engine_type = "ActiveMQ"
engine_version = var.activemq_engine_version
host_instance_type = "mq.t3.micro"
user {
username = "appuser"
password = var.broker_password
}
}
After
hcl
resource "aws_mq_broker" "broker" {
broker_name = "app-broker"
engine_type = "ActiveMQ"
engine_version = var.activemq_engine_version
host_instance_type = "mq.t3.micro"
tags = {
Service = "messaging"
Environment = "production"
}
user {
username = "appuser"
password = var.broker_password
}
}